Security Policy with URLs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Security Policy with URLs

L1 Bithead

Is it possible to create a Security Policy with the Destination address as a URL? I would prefer to use the URL to avoid using the IP in case the destination service changes it.

Thanks,

Dennis

1 accepted solution

Accepted Solutions

L4 Transporter

Yes, create an address object, use the FQDN from the drop down, and enter your URL.

I believe the refresh job runs every 30 minutes to convert that URL to an IP address.

View solution in original post

4 REPLIES 4

L4 Transporter

Yes, create an address object, use the FQDN from the drop down, and enter your URL.

I believe the refresh job runs every 30 minutes to convert that URL to an IP address.

In that case dont forget to add a url-filter aswell for the same FQDN (specially if this is http traffic).

The bad part (security wise) of using FQDN as dstip is that you will rely on what answer the external (compared to the PA itself) dns will bring you.

Thanks, creating the address object worked.

This is not http traffic, it's secure FTP (as best it can be) on uncommon ports. I will keep the url-filtering underadvisement.

Thanks.


  • 1 accepted solution
  • 4975 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!